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(g) Secure document and method and apparatus for producing and authenticating same. 



A document secure against tampering or al- 
teration and method and apparatus for produc- 
ing and authenticating such a document A 
document is scanned to produce a digital signal 
which is compressed, encrypted, and coded as 
a two dimensional barcode or as some other 
appropriate form of coding, which is incorpo- 
rated into a label which is the affixed to the 
document. In one embodiment the signal repre- 
senting the image is encrypled using a public 
key encryption system and the key is 
downloaded from a center. This key maybe 
changed from time to time to increase security. 
To facilitate authentication the corresponding 
decryption key is encrypted with another key 
and incorporated on the card. To validate the 
document the coded signal is scanned from the 
label, decoded, decrypted, expanded and dis- 
played. The card may then be authenticated by 
comparison of the displayed representation of 
the image and the document. 
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The subject invention relates to a document or 
similar item. More particularly, it relates to a docu- 
ment or similar item which has a high degree of se- 
curity against tampering, and to methods and appa- 
ratus for producing and authenticating such docu- 
ments. 

U.S. patent no. 4.853.961; for: "Reliable Docu- 
ment Authentication System", to: Pastor; issued: Au- 
gust 1 . 1989. discloses a system wherein a document 
is authenticated by encryption using a public key en- 
cryption system. The invention of the Pastor patent 
teaches authenticnt on of a document by encryption 
of information derived from the document, incorpor- 
ating that enc/ ypted information into the document, 
recovering the encrypted information from the docu- 
ment and decrypting a. and comparing it to the infor- 
mation as originally inauddd m the document. 

While believed to generally very effective for 
authenticating -documents to detect alteration or tam- 
pering, the ahov* d^smbed invention suffers from 
certain disadvantages w.th existing documents, or 
document s which are produced to an already defined 
format. For easting documents it is necessary to in- 
put information from the document to create the en- 
crypted informal on T/pically. this would be done 
either by manual ke /board input or by some form of 
character recogn.tion technology. Also, where docu- 
ments are produced in large numbers to already de- 
fined format e.g. driver's licenses, it is difficult to 
modify the format to provide for incorporation of the 
encrypted information in accordance with the Pastor 
patent. 

The above disadvantages of the prior art are 
overcome in accordance with the subject invention by 
means of a method and apparatus for producing a se- 
cure document and for authenticating that document. 
Apparatus for producing a secure document includes 
a scanner for producing a first signal representative 
of an image of the document The apparatus further 
includes an encrypter for encrypting a second signal, 
which is derived, at least in part, from the first signal, 
and which includes a representation of the image; 
and a coder for incorporating a coded representation 
of the encryption of the second signal onto a label to 
be affixed to the document. 

(As used herein the term "label" preferably de- 
scribes a conventional label such as an address label. 
However, it is within the contemplation of the subject 
invention, and as used herein the term "label" means, 
any object which may incorporate the coded repre- 
sentation and which can be affixed or otherwise per- 
manently associated with the document.) 

Apparatus for authenticating a document so pro- 
duced includes a reader for reading the coded repre- 
sentation of the second signal from the affixed label, 
a decoder for decoding the coded representation of 
the second signal, a decrypter for decrypting the de- 
coded signal, and a display for displaying the repre- 



sentation of the image incorporated in the second 
signal. 

In accordance with the method of the subject in- 
vention the document to be secured is scanned to 
5 produce the first signal. The second signal, which is 
derived at least in part from the first signal, and which 
includes a representation of the image is encrypted 
and coded and incorporated in the label to be affixed 
to the document. 
10 Once produced the document is then authenti- 

cated by reading the coded representation of the sec- 
ond signal from the affixed label, decoding and de- 
crypting the second signal, and controlling a display 
in accordance with the decrypted second signal to 
15 display the representation of the image which is in- 
cluded in the second signal. The displayed represen- 
tation of the image and the document are then com- 
pared to authenticate the document as free from tam- 
pering or attention. 
20 Thus, it is an advantage of the subject invention 

to provide a method and apparatus for producing a 
secure document, which are easily applied to existing 
documents or documents produced in a predefined 
format. 

25 In accordance with one aspect of the subject in- 

vention the first signal is converted into a digital sig- 
nal for processing. 

In accordance with another aspect of the subject 
invention the second signal includes a compressed 
30 form of the first signal. 

(Signal compression is well known to those skil- 
led in the art and, in the case of digital signals, in- 
volves the application of a predetermined algorithm 
to a signal to reduce the number of bytes which must 
35 transmitted or processed, while still retaining sub- 
stantially all of the information represented by the 
signal.) 

In accordance with another aspect of the subject 
invention the second signal is encrypted using an en- 
40 cryption key Ej, for a public key encryption system. 

In accordance with still another aspect of the 
subject invention a decryption key, Dj which corre- 
spondences to the key, E h is encrypted with a second 
encryption key, E 1f for the public key encryption sys- 
45 tern, and the resulting encrypted decryption key 
E,[Dj], is appended to the encrypted second signal pri- 
or to incorporation of the second signal into the sec- 
ond portion of the document. 

In accordance with still another aspect of the 
50 subject invention the encrypted second signal is 
printed on a label as a two dimensional barcode. 

In accordance with yet still another aspect of the 
second invention the apparatus for authenticating 
the document card stores a decryption key D h corre- 
55 sponding to key E, and the decryption of the encrypt- 
ed second signal includes the step of decrypting the 
encrypted key, EJDJ, using the decryption key, D 1( 
to obtain the decryption key Dj. which may then be 
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used lo decrypt the encrypted second signal. 

Thus, It can be seen that the subject invention 
achieves the above slated advantages by providing a 
method and apparatus for producing a secure docu- 
ment which includes an image which may be easily 5 
compared to document, and which is highly resistant 
to tampering. Other advantages of the subject inven- 
tion will be readily apparent to those skilled in. the art 
from consideration of the attached drawings and the 
detailed description of a preferred, exemplary em- 10 
bodiment set forth below. 

In the drawings: 

Figure 1 is a schematic block diagram of an ap- 
paratus for producing a secure document in accor- 
dance with the subject invention. 15 

Figure 2 is a schematic block diagram of an ap- 
paratus for authenticating a secure document pro- 
duced in accordance with the subject invention. 

Figure 1 shows a schematic block diagram of ap- 
paratus 10 for producing a label L AjJocument for 20 
which the label is intended is scanned by a conven- 
tional video scanner 12 to produce a first signal rep- 
resentative of that document D's image. Preferably, 
the first signal is then converted to a digital form by 
an anafog-lo-digital convenor 14 for processing in the 25 
• digital domain. It is however within the contemplation 
of the subject invention that at least the signal com- 
pression and encryption techniques to be described 
below may be carried out in the analog domain using 
signal compression and scrambling technologies well 30 
known lo those in the analog signal processing arts. 

In one embodiment of the subject invention, 
scanning and compression are done using well known 
Group Hi facsimile technology, though other suitable 
scanning and compression methods are within the 35 
contemplation of the subject invention. 

The first signal is then input to a compression 
module 16 where it is compressed to reduce the 
amount of data which must be stored on label L. 

H should be noted that where label L is to have 40 
substantially the same form as an address label or 
the like, data compression is, at the present state of 
technology, necessary. However, with anticipated 
improvements in data storage technology, or in appli- 
cations where the document may comprise a high ca- 45 
pacity storage medium (e.g. a floppy disk), it is within 
the contemplation of the subject invention that the 
first signal may not require compression but that the 
full signal may be processed as will be described fur- 
ther below. 5Q 

Data compression algorithms, for compression of 
image signals, are known to those skilled in the art. 
Preferably scanning and signal compression are car- 
ried out in accordance with the well known standard 
for Group III facsimile transmission. Further descrip- 55 
lion of the operation of compressor 16 is not believed 
necessary to an understanding of the subject inven- 
tion. 



The compressed first signal is then input to an 
encrypter 20 to be included in the encrypted second 
signal which will be incorporated into label L as will be 
described further below. Preferably encrypter 20 en- 
crypts the second signal using an encryption key, E,, 
for a public key encryption system such as the well 
known RSA system. 

The encrypted second signal is then encoded in 
accordance with some predetermined format by cod- 
er module 22, which controls code generator 24 to in- 
corporate the encoded encrypted second signal in a 
portion of document. 

In accordance with a preferred embodiment of 
the subject invention the coded signal is coded as a 
two dimensional barcode, such as the PDF-41 7 stan- 
dard barcode, developed by the Symbol Technology 
Corporation of New York. However, the encrypted 
second signal may be coded into any suitable format. 
For example, for a smart card or a memory card coder 
22 and code generator 24 may store the coded sec- 
ond signal as an appropriately formatted binary data 
block. 

In the preferred embodiment where the coded 
second signal is represented as a two dimensional 
barcode the barcode will preferably be printed on lab- 

e]_L. 

In a preferred embodiment of the subject inven- 
tion compressor module 16, encrypter module 20, 
and coder module 22 are implemented as software 
modules in microprocessor 26; which is preferably, an 
Intel model 80386, or the like, or other microproces- 
sors of greater capacity. 

In a preferred embodiment of the subject inven- 
tion a center 40 transmits encryption code E { to en- 
crypter module 20. In order to increase the security 
of label L key E, maybe changed from time to time. 
For the highest level of security key E, maybe 
changed for each card C produced, or a different key 
may even be used to encrypt different portions of the 
second signal. 

To facilitate decryption of the second signal in an 
environment where key E, is frequently changed cen- 
ter 40 also transmits an encrypted decryption key 
E r [D|] to be appended to the encrypted second signal 
by coder module 22. Thus, as will be seen below, 
when document D is to be authenticated the neces- 
sary decryption key D, can be obtained by decrypting 
Ei[OJ. 

Typically, encryption/decryption pair E,, D, will 
remain substantially constant during operation of sys- 
tem 10. However, in applications where system 10 is 
used to produced labels L for various organizations 
different pairs Ej may be used for different organ- 
izations. 

Turning now lo Figure 2 apparatus 50 for authen- 
ticating a labeled document LD, having label L affixed 
is shown. The label L of card C is scanned by a bar- 
code scanner 52 having the capability to scan an ap- 



NSOOCID- <EP__. 06006<16A2_I_> 



EP 0 600 646 A2 



propriate two dimensional barcode. The scanned sig- 
nal is then decoded by decoder module 54 and de- 
crypted by decrypter module 58. In a preferred em- 
bodiment of the subject invention decrypter 58 stores 
decryption key D, which is used lo decrypt encrypted 5 
key E^Di] to obtain decryption key Dj. Key D 4 is then 
used to decrypt the decoded signal scanned from lab- 
el L. 

Key D, is obtained by decrypter 58 from center 
40. Typically, D, will remain constant during operation 10 
of system 50, as described above, and a direct com- 
munication link between system 50 and center 40 is 
not necessary and key D, maybe transmitted in any 
convenient manner. However, for example, in one ap- 
plication, where label L has a predetermined expira- 15 
tion date it may be desirable to change key D n after 
the expiration dale and if such expiration dates occur 
sufficiently often a direct communication link to cen- 
ter 40 maybe included in system 50. 

The decrypted scan signal is t hen expanded in by 20 
an algorithm complimentary to the compression algo- 
rithm used in system 10, in a conventional manner 
which need not be described further for an under- 
standing of the subject invention. 

In a preferred embodiment of the subject inven- 25 
tion decoder module 54, decrypter module 58, and 
expander module 60 maybe implemented as soft- 
ware modules in a microprocessor 61. 

The decrypted, expanded signal is then dis- 
played by a conventional display 62. The display in- 30 
eludes a representation Rl of the image of document 
D. To authenticate labeled document LD it is com- 
pared with representation RL It should be noted that 
with compression representation Rl will be somewhat 
degraded. It has been found however that using the 35 
above described Group HI facsimile standard a suffi- 
ciently accurate representation of an image of an 8 
1/2x11 size text document may be coded as approx- 
imately 2,000 bytes of data and printed using the 
above described PDF-417 two dimensional barcode 40 
in an area of approximately 3.5 by 2.5 inches. Of 
course, as described above, with improvements in 
storage technology and/or the use of media having a 
higher data storage capacity as embodiments of label 
L representation Rl can be arbitrarily accurately. 45 

The preferred embodiments described above 
have been given by way of example only, and other 
embodiments of the subject invention will be appa- 
rent to those skilled in the art from consideration of 
the detailed descriptions set forth above and the at- 50 
tached drawings. Accordingly, limitations on the sub- 
ject invention are to be found only in the claims set 
forth below. 

55 

Claims 

1. A method of producing and authenticating a se- 



cure document comprising the steps of: 

a) scanning said document lo produce a first 
signal representative of an image of said at 
least a portion of said document; 

b) encrypting a second signal, comprising a 
representation of said image, said second 
signal being derived at least in part from said 
first signal; 

c) incorporating a coded representation of 
said encrypted second signal with said docu- 
ment; 

d) reading said coded representation of said 
second signal from said document; 

e) decoding said second signal: 

f) decrypting said decoded second signal; 

g) inputting said decrypted second signal to a 
display to display said representation of said 
image; 

h) comparing said document to said displayed 
image to authenticate said document. 

2. A method as claimed in claim 1 wherein said sec- 
ond signal comprises a compressed form of said 
first signal. 

3. A method as claimed in claim 1 or claim 2 where- 
in said second signal is encrypted using an en- 
cryption key. Ej. for a public key encryption sys- 
tem. 

4. A method as claimed in claim 3 wherein a decryp- 
tion key, Dj, corresponding to said encryption 
key, E lf is encrypted with a second encryption 
key, E,, for said public key encryption system. 

5. A method as claimed in claim 4 wherein said en- 
crypted decryption key, E,[Dd, is appended lo 
said encrypted second signal prior to incorpora- 
tion with said document. 

6. A met hod as claimed in claim 5 wherein said rep- 
resentation of said encrypted second signal is in- 
corporated with said document as a two dimen- 
sional barcode. 

7. A method as claimed in claim 5 wherein decryp- 
tion of said encrypted second signal comprises 
the further steps of decrypting said encrypted 
key, E t [Dj] using a decryption key, D,. 

8. A method as claimed in any of claims 2 to 7 
wherein said encrypted second signal is incorpo- 
rated with said document as a two dimensional 
barcode. 

9. A method as claimed in any preceding claim 
wherein said coded representation is incorporat- 
ed into a label and said label is affixed to said 
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document. 

10. A melhod for authenticating a document, said 
document having a coded representation of an 
encrypted siynal comprising a representation of 5 
an image of at least a portion of said document, 
with said document, comprising the steps of: 

a) reading said coded representation of said 
signal from said document, 

b) decoding said coded representat ion of said 10 
signal; 

c) decrypting said encrypted representation 
of said signal; and, 

d) inputting said decrypted representation of 
said signal to a display for displaying said rep- 15 
resentation of said image; whereby, 

e) said document may be authenticated by 
comparison of said document with said dis- 
played representation of said image. 

20 

11. A method as claimed in claim 10 wherein said en- 
crypted signal is encrypted using an encryption 
key, E f . for a public key encryption system. 



25 



12. A method as claimed in claim 11 wherein a de- 
cryption key, D, corresponding to said key E,, is 
encrypted with a second encryption key E, for 
said public key encryption system to form an en- 
crypted decryption key, E,[D,], and said encrypt- 
ed decryption key, E,[DJ is appended to said en- 30 
crypled signal, and wherein said decryption step 
further comprises the steps of; 

a) decrypting said encrypted decryption key, 
E,[D { ] wit ha corresponding decryption key, D,, 

to recover said decryption key D,; and, 35 

b) decrypting said encrypted signal with said 
key. D,. 

13. Apparatus for authenticating a document, said 

document having a coded representation of an 40 
encrypted signal compressing a representation 
of a image of at least a portion of said document 
incorporated with said document, comprising: 

a) means for reading said coded representa- 
tion of said signal from said document; 45 

b) decoding means, responsive to said read- 
ing means for decoding said coded represen- 
tation of said signal; 

c) decrypting means, responsive to said de- 
coding means, for decrypting said decoded 50 
representation of said signal, and, 

d) display means, responsive to said decrypt- 
ing means, for displaying said representation 
of said image: whereby, 

e) said document may be authenticated by 55 
comparison of said document with said dis- 
played representation of said image. 



1 4. An apparatus as claimed in claim 1 3 wherein said 
encrypted signal is encrypted using an encryp- 
tion key, E ( , for a public key encryption system. 

15. Apparatus as claimed in claim 14 wherein a de- 
cryption key, D,, corresponding to said key E,, is 
encrypted with an encryption key E, for said pub- 
lic key encryption system to form an encrypted 
decryption key ErfD,), and said encrypted de- 
cryption key E,[DJ is appended to said encrypted 
signal, and said decrypting means further com- 
prises: 

a) means for decrypting said encrypted de- 
cryption key, E,[D f ] with a corresponding de- 
cryption key, D, t to recover said decryption 
key, D,; and 

b) means for decrypting said encrypted signal 
using said key, D,. 

16. A document, comprising an encoded representa- 
tion of an encrypted signal comprising a repre- 
sentation of an image of at least a portion of said 
document. 

17. A document as claimed in claim 16 wherein said 
digital signal is encrypted using an encryption 
key, E,. for a public key encryption system. 

18. A document as claimed in claim 17 wherein a de- 
cryption key, D } , corresponding to said encryp- 
tion key, E,, is encrypted with a second encryp- 
tion key, E,, for said public key encryption system 
to produce an encrypted description key, E,[Dj], 
and said encrypted decryption key, E,[D } ], is ap- 
pended to said digital signal prior to incorporation 
with said document. 

19. A document as claimed in claim 16 wherein said 
representation of said encrypted digital signal is 
incorporated with said document portion as a two 
dimensional barcode. 

20. A label for securing in, to or in association with an 
associated document, said label incorporating an 
encoded representation of an encrypted signal, 
said signal comprising a representation of an im- 
age of said document. 
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(54) Secure document and method and apparatus for producing and authenticating same 



(57) A document secure ag-i "si tampering or alter- 
ation and method and apparatus lor prrviucing and au- 
Ihenlicaling such a document A document >s scanned 
to produce a digital signal winch rs compressed, en- 
crypted, and coded as a two cumcnsiorMl barcode or as 
some other appropriate form of ccctnc which is incor- 
porated into a label which is Ihc affixed to the document. 
In one embodiment the signal representing the image is 
encrypted using a public key encyptton system and the 



key is downloaded from a center. This key maybe 
changed from time to time to increase security. To facil- 
itate authentication the corresponding decryption key is 
encrypted with another key and incorporated on the 
card. To validate the document Ihe coded signal is 
scanned from the label, decoded, decrypted, expanded 
and displayed. The card may then be authenticated by 
comparison of the displayed representation of the image 
and the document. 
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